Your data stays yours.
Full stop.
IntakeOS is built for enterprise teams sharing sensitive process intelligence. We treat that responsibility seriously - with architectural decisions, contractual commitments, and a compliance roadmap designed to give your security team every answer they need.

SOC 2 Type II - Observation period
Audit engagement underway. Controls are being evaluated over time.
TLS 1.3 + AES-256 encryption
All data encrypted in transit and at rest.
Zero model training on your data
Contractual and architectural guarantee.
We never train AI models
on your process data.
When your team describes a process to VARA, that information is used exclusively to conduct your intake and generate your report. It is never pooled, aggregated, or used to improve AI models - not ours, not our providers'.
This isn't a policy preference - it's a hard architectural and contractual constraint enforced at every layer of the stack. We operate our AI calls through provider agreements that explicitly prohibit training on API inputs. Your process intelligence is competitively sensitive; we treat it that way.
AI providers contractually prohibited from training on your inputs
No cross-tenant data sharing or model fine-tuning
Intake transcripts scoped to your organisation - never visible to other customers
You own your data. We are custodians, not owners.
Data deletion requests honoured within 30 days
What happens to your data
Intake conversation
VARA's questions and your team's answers are sent to an AI inference endpoint over TLS. The prompt is processed and discarded - never stored by the model provider.
Report generation
Your answers feed the deterministic scoring engine first. AI is then called to enrich explanations. The generated report is stored encrypted in your tenant's isolated data partition.
At rest
Reports, transcripts, and attachments live in AES-256 encrypted storage, scoped to your organisation. No IntakeOS employee can read your data without an approved access request logged in our audit trail.
On deletion
When you request deletion, data is purged from primary storage within 30 days and from backups within 90 days. You receive written confirmation.
Working toward SOC 2 Type II
We've engaged a registered audit firm and are actively building toward SOC 2 Type II certification. Here's where we stand and what's next.
Security controls documented
All security policies, access control procedures, change management, and incident response playbooks are written, reviewed, and version-controlled.
Controls implemented
Technical controls (encryption, RBAC, SSO, audit logging, MDM) are deployed across all production infrastructure and corporate devices.
Observation period
We are currently in our formal observation window with our auditors to prove consistent adherence to our documented controls over time.
Need our security documentation now?
We can share our current security controls summary, data processing addendum (DPA), and sub-processor list under NDA. Enterprise customers receive these as part of the onboarding package.
Security built into every layer
Defence-in-depth isn't a buzzword for us - it's how we architect every service. Here's what's in place today.
Encryption everywhere
- TLS 1.3 for all data in transit - no unencrypted channels
- AES-256 at rest for database rows, object storage, and backups
- Secrets managed in a dedicated secrets vault, never in environment variables or source code
- Database credentials rotated automatically on a fixed schedule
Access control
- Role-based access control (RBAC) - Admin, Business User, and Staff roles with least-privilege defaults
- Multi-tenant isolation: each organisation's data is logically separated with organisation-scoped queries enforced at the API layer
- Internal staff access to production requires a tracked, time-limited access request
- All admin actions are written to an immutable audit log with actor, action, timestamp, and IP
Infrastructure
- Hosted on enterprise-grade cloud infrastructure with 99.9% uptime SLA
- Data residency in the United States; EU region available for enterprise contracts
- Automated backups with point-in-time recovery, retained for 30 days
- Separate production, staging, and development environments - no production data in dev or staging
Monitoring & detection
- Centralised structured logging for every API request - response times, status codes, user context
- Anomaly detection alerts for unusual access patterns or bulk data exports
- Dependency vulnerability scanning on every build; critical CVEs trigger same-day patches
- Penetration testing conducted annually by an independent third party
Incident response
- Documented incident response plan with defined severity levels (P0–P3)
- Security incidents affecting customer data disclosed within 72 hours of discovery
- Dedicated security contact: security@intakeos.ai - monitored 24/7
- Post-incident reviews published for P0 and P1 events
AI sub-processors
- AI inference routed only to providers with enterprise data processing agreements in place
- Agreements explicitly prohibit use of API inputs for model training or improvement
- Sub-processor list maintained and shared on request; customers notified of additions 30 days in advance
- AI calls include no PII in system prompts - process descriptions only, never employee names or contact data unless voluntarily provided
Security starts with our team
Technical controls only go so far. We invest equally in making sure the humans operating the platform understand, own, and enforce our security posture.
Background checks
All employees and contractors with access to production systems undergo identity verification and background screening before their first day.
Security awareness training
Mandatory security training at onboarding, plus quarterly refreshers covering phishing, social engineering, and safe data handling.
Least-privilege access
No engineer has standing access to production data. Access is granted on request, scoped to the minimum required, time-limited, and fully logged.
Device security
Company-issued devices require full-disk encryption, MDM enrollment, and auto-lock. Personal devices are prohibited from accessing production systems.
Our sub-processors are held to the same standard
We review every third-party vendor before onboarding and require data processing agreements that mirror the commitments we make to you.
Vendor security reviews
Every sub-processor must complete a security questionnaire and demonstrate adequate controls before we integrate their service.
DPA coverage
All vendors processing personal or intake data sign a Data Processing Addendum that includes purpose limitations, data deletion requirements, and breach notification SLAs.
30-day sub-processor notice
We notify customers at least 30 days before adding a new sub-processor that will touch your data. You have the right to object.
Annual vendor re-review
Sub-processors are reviewed annually. Any vendor failing to maintain adequate security controls is offboarded.


Questions your security team will ask
We've answered the most common ones below. If you need anything else, email security@intakeos.ai.
Does IntakeOS use my intake data to train AI models?
Where is my data stored?
Who inside IntakeOS can see my intake data?
Are you GDPR compliant?
What happens if there's a security breach?
Can I delete my data?
Do you conduct penetration testing?
When will SOC 2 certification be complete?
Have more questions?
Our team is ready.
We're happy to complete your vendor security questionnaire, provide our DPA, join a security review call, or connect you directly with our compliance lead.
We aim to respond to all security enquiries within one business day.
